* [PATCH 1/3] smb: client: refactor ACL setting control flow in id_mode_to_cifs_acl()
@ 2026-06-22 1:08 Steve French
2026-06-22 1:08 ` [PATCH 2/3] smb/client: fix security flag calculation when setting security descriptors Steve French
2026-06-22 1:08 ` [PATCH 3/3] smb/client: fix chown/chgrp with SMB3 POSIX Extensions Steve French
0 siblings, 2 replies; 3+ messages in thread
From: Steve French @ 2026-06-22 1:08 UTC (permalink / raw)
To: linux-cifs; +Cc: Ralph Boehme, Steve French
From: Ralph Boehme <slow@samba.org>
Refactor the control flow in id_mode_to_cifs_acl() to reduce nesting and
prevent error code overwriting.
Instead of wrapping the call to ops->set_acl() in a conditional block,
introduce early exits (goto id_mode_to_cifs_acl_exit) when build_sec_desc()
fails or ops->set_acl is NULL. This ensures that any actual error returned
by build_sec_desc() is not overwritten with -EOPNOTSUPP.
Signed-off-by: Ralph Boehme <slow@samba.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
---
fs/smb/client/cifsacl.c | 16 ++++++++++------
1 file changed, 10 insertions(+), 6 deletions(-)
diff --git a/fs/smb/client/cifsacl.c b/fs/smb/client/cifsacl.c
index 42a3115359da..5bbf73736358 100644
--- a/fs/smb/client/cifsacl.c
+++ b/fs/smb/client/cifsacl.c
@@ -1834,14 +1834,18 @@ id_mode_to_cifs_acl(struct inode *inode, const char *path, __u64 *pnmode,
cifs_dbg(NOISY, "build_sec_desc rc: %d\n", rc);
- if (ops->set_acl == NULL)
- rc = -EOPNOTSUPP;
+ if (rc != 0)
+ goto id_mode_to_cifs_acl_exit;
- if (!rc) {
- /* Set the security descriptor */
- rc = ops->set_acl(pnntsd, nsecdesclen, inode, path, aclflag);
- cifs_dbg(NOISY, "set_cifs_acl rc: %d\n", rc);
+ if (ops->set_acl == NULL) {
+ rc = -EOPNOTSUPP;
+ goto id_mode_to_cifs_acl_exit;
}
+
+ /* Set the security descriptor */
+ rc = ops->set_acl(pnntsd, nsecdesclen, inode, path, aclflag);
+ cifs_dbg(NOISY, "set_cifs_acl rc: %d\n", rc);
+
id_mode_to_cifs_acl_exit:
cifs_put_tlink(tlink);
--
2.53.0
^ permalink raw reply related [flat|nested] 3+ messages in thread* [PATCH 2/3] smb/client: fix security flag calculation when setting security descriptors
2026-06-22 1:08 [PATCH 1/3] smb: client: refactor ACL setting control flow in id_mode_to_cifs_acl() Steve French
@ 2026-06-22 1:08 ` Steve French
2026-06-22 1:08 ` [PATCH 3/3] smb/client: fix chown/chgrp with SMB3 POSIX Extensions Steve French
1 sibling, 0 replies; 3+ messages in thread
From: Steve French @ 2026-06-22 1:08 UTC (permalink / raw)
To: linux-cifs; +Cc: Ralph Boehme, Steve French
From: Ralph Boehme <slow@samba.org>
In id_mode_to_cifs_acl(), aclflag was initialized to CIFS_ACL_DACL by default.
This forced the client to request setting the DACL even when only an ownership
(chown) or group (chgrp) change was being performed.
Let build_sec_desc() do the proper flag calculation by initializing aclflag
to 0. build_sec_desc() sets the appropriate bits (CIFS_ACL_OWNER, CIFS_ACL_GROUP,
or CIFS_ACL_DACL) depending on what actually changed.
If build_sec_desc() results in aclflag being 0 (meaning no changes were mapped),
exit early to avoid sending an empty security descriptor update to the server.
Signed-off-by: Ralph Boehme <slow@samba.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
---
fs/smb/client/cifsacl.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/fs/smb/client/cifsacl.c b/fs/smb/client/cifsacl.c
index 5bbf73736358..535f3e8d6b92 100644
--- a/fs/smb/client/cifsacl.c
+++ b/fs/smb/client/cifsacl.c
@@ -1738,7 +1738,7 @@ id_mode_to_cifs_acl(struct inode *inode, const char *path, __u64 *pnmode,
kuid_t uid, kgid_t gid)
{
int rc = 0;
- int aclflag = CIFS_ACL_DACL; /* default flag to set */
+ int aclflag = 0;
__u32 secdesclen = 0;
__u32 nsecdesclen = 0;
__u32 dacloffset = 0;
@@ -1837,6 +1837,11 @@ id_mode_to_cifs_acl(struct inode *inode, const char *path, __u64 *pnmode,
if (rc != 0)
goto id_mode_to_cifs_acl_exit;
+ if (aclflag == 0) {
+ cifs_dbg(FYI, "set_cifs_acl aclflag=0, no change mapped\n");
+ goto id_mode_to_cifs_acl_exit;
+ }
+
if (ops->set_acl == NULL) {
rc = -EOPNOTSUPP;
goto id_mode_to_cifs_acl_exit;
--
2.53.0
^ permalink raw reply related [flat|nested] 3+ messages in thread* [PATCH 3/3] smb/client: fix chown/chgrp with SMB3 POSIX Extensions
2026-06-22 1:08 [PATCH 1/3] smb: client: refactor ACL setting control flow in id_mode_to_cifs_acl() Steve French
2026-06-22 1:08 ` [PATCH 2/3] smb/client: fix security flag calculation when setting security descriptors Steve French
@ 2026-06-22 1:08 ` Steve French
1 sibling, 0 replies; 3+ messages in thread
From: Steve French @ 2026-06-22 1:08 UTC (permalink / raw)
To: linux-cifs; +Cc: Ralph Boehme, stable, Steve French
From: Ralph Boehme <slow@samba.org>
Ownership (chown) and group (chgrp) modifications were being ignored when
mounting with SMB3 POSIX Extensions unless CIFS_MOUNT_CIFS_ACL or
CIFS_MOUNT_MODE_FROM_SID were also explicitly set.
Fix this by checking for posix_extensions in cifs_setattr_nounix() when
updating UID and GID, ensuring that id_mode_to_cifs_acl() is called to map
and set the ownership/group information on the server.
Cc: stable@vger.kernel.org
Signed-off-by: Ralph Boehme <slow@samba.org>
Signed-off-by: Steve French <stfrench@microsoft.com>
---
fs/smb/client/inode.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/smb/client/inode.c b/fs/smb/client/inode.c
index 51fb7c418d52..56b0f109e41b 100644
--- a/fs/smb/client/inode.c
+++ b/fs/smb/client/inode.c
@@ -3376,7 +3376,8 @@ cifs_setattr_nounix(struct dentry *direntry, struct iattr *attrs)
if (attrs->ia_valid & ATTR_GID)
gid = attrs->ia_gid;
- if (sbflags & (CIFS_MOUNT_CIFS_ACL | CIFS_MOUNT_MODE_FROM_SID)) {
+ if ((sbflags & (CIFS_MOUNT_CIFS_ACL | CIFS_MOUNT_MODE_FROM_SID)) ||
+ cifs_sb_master_tcon(cifs_sb)->posix_extensions) {
if (uid_valid(uid) || gid_valid(gid)) {
mode = NO_CHANGE_64;
rc = id_mode_to_cifs_acl(inode, full_path, &mode,
--
2.53.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-06-22 1:12 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-06-22 1:08 [PATCH 1/3] smb: client: refactor ACL setting control flow in id_mode_to_cifs_acl() Steve French
2026-06-22 1:08 ` [PATCH 2/3] smb/client: fix security flag calculation when setting security descriptors Steve French
2026-06-22 1:08 ` [PATCH 3/3] smb/client: fix chown/chgrp with SMB3 POSIX Extensions Steve French
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).